Layer scans by stage
Secret detection belongs in a pre-commit hook and again in CI, because a committed credential is compromised the moment it lands. Static analysis runs on pull requests against changed files. Dependency scanning runs on every build and again on a schedule, since new vulnerabilities appear in code that has not changed. Container image scanning runs after build against the exact digest that will ship. Infrastructure-as-code policy checks run against the plan output.
Each layer catches a different class of problem, and each runs where the fix is cheapest.
Gate on severity and reachability, not on count
Block merges on critical and high findings that are actually reachable from application code. Report everything else without blocking. Reachability analysis is what separates a usable gate from a wall of transitive-dependency noise that nobody reads.
Give every gate a documented exception path with an owner and an expiry date. Exceptions without expiry become permanent, and permanent exceptions are how gates die.
Generate provenance and an SBOM at build time
Produce a software bill of materials with every artifact and sign both the image and its attestation. When a new critical vulnerability is disclosed, the difference between an hour of triage and a week of archaeology is whether you can query which running images contain the affected package.
Store SBOMs alongside artifacts and keep them for as long as the artifact could plausibly still be running somewhere.
Make results fast and local
Post findings as inline pull-request comments on the offending line, with a suggested fix where the tool supports one. Keep the total added pipeline time under a few minutes by caching vulnerability databases and running scanners in parallel. Slow security tooling gets routed around, and routed-around tooling protects nothing.
Key takeaways
- Run secret, SAST, dependency, container, and IaC scans at distinct pipeline stages.
- Block only on reachable critical and high findings; report the rest.
- Require an owner and expiry date on every exception.
- Emit and retain a signed SBOM with each artifact for fast disclosure triage.
- Deliver findings inline on the pull request and keep scan time to minutes.
Need a pod that already works this way?
DevGrid Staffing assembles managed DevOps, platform, and SRE pods with the compliance and delivery practices described here built in from week one.
